IT Policies and Guidelines
CONTENTS:
Policies form the foundation of any security program. Policies define how ITS will approach security, how employees (staff/faculty) and students are to approach security, and how certain situations will be handled.
While this web page lists many university IT policies, it is not an exhaustive list. Regulations, policies and procedures are constantly evolving. Laws, policies, and regulations not specific to information technology may also apply, e.g.: student conduct, personnel policy or contract, sexual harassment, chain letter laws, etc.
University of California policies and guidelines specific to computer/network resources:
- University of California IT Policies
- University of California Electronic Communications Policy
- Digital Copyright Protection at the University of California
- Management Guide for Information Security
- UC Business and Finance Bulletins -- IS Series - Information Systems
- President Yudof's Statement on Social Security Numbers - Feb. 10, 2010 (PDF)
UC Santa Cruz policies and guidelines specific to computer/network resources:
UCSC Information Security Program Framework Diagram (PDF)
Log of Policy Updates
Glossary of selected terms in UCSC IT-related policies, procedures and guidelines
CAMPUS POLICIES AND PROCEDURES
- Campus Policies:
- Policy for Acceptable Use of UCSC Electronic Information Resources ("Acceptable Use Policy" or "AUP")
- Minimum Network Connectivity Requirements Policy
- Password Policy
- UCSC Implementation of the UC Electronic Communications Policy (ECPI)
- HIPAA Security Rule Compliance Policy
- Log Policy - NEW June 2012
- Procedures supporting the above campus policies:
- Understanding UCSC's Minimum Network Connectivity Requirements
- UCSC Password Strength and Security Standards
- "Access Without Consent" Process and Form (PDF)
- Notice about Access to Records upon Employee Separation - updated June 2012
- ITS Routine System Monitoring Practices
- SSN Scanning Methodology
- Implementing UCSC's HIPAA Security Rule Compliance Policy
- Log Procedures - NEW June 2012
- Other campus policy statements:
- PII Inventory and Security Breach Procedures
- UC Santa Cruz ResNet Responsible Use Policy (coming soon)
- Instructional Computing Lab Policy Summary
- SSL Certificate Policy
- Proposed update - 5/29/13
- Electronic Official Communications Statement
Protection of Social Security Numbers: Letter to campus from CP/EVC Kliger and VC IT Doyle - April 2010
- Practices for Protecting Electronic Restricted Data
- Protection Matrix
- IS-3 Assessment Template (Excel)
- Security Issue Matrix: Blank (Word) / Seeded (Word) / Instructions
- University Administrative Information Systems, Access to Information Statement (PDF)
(all individuals with access to restricted data should read and sign)
ADDITIONAL PRACTICES, PROCEDURES AND GUIDELINES
- Data Security Contract Language
- Digital Millennium Copyright Act (DMCA) at UC Santa Cruz
- Use of Free/Low Cost IT Services - updated 1/23/13
- UCSC Plan for Combating Unauthorized Distribution of Copyrighted Materials
- Procedures for Blocking Network Access
- ITS Backup Retention Standards
- Payment Card Industry Data Security Standard (PCI DSS) Compliance at UCSC
- Remote Access Requirements
- Secure Browser Settings
- Security Standards and Resources
INFORMATION TECHNOLOGY SERVICES (ITS) DIVISIONAL POLICIES
- ITS Commercial Endorsement Policy
- ITS Policy Regarding Personal Identity Information (PII)
- Instructions for information requests from FBI/Federal Law Enforcement
- ITS Sanction Information
- Procedures for responding to compromised computers
Other General UC and UCSC Policies and Resources:
- UC Systemwide Policies and Guidelines
- UC Santa Cruz Policies and Procedures
- Student Policies and Regulations Handbook
- Title IX/Sexual Harassment Office
- University Police
Local, State, or Federal laws
- United States Code from the Office of the Law Revision Counsel under the U.S. House of Representatives
- California legislative information, maintained by the Legislative Counsel of California
- United States Copyright Office
Draft UC Santa Cruz Information Technology policies, guidelines, and practices. Please forward feedback to itpolicy@ucsc.edu
- Digital Certificate Policy (update of SSL Certificate Policy) - updated 5/29/13
- WiFi Policy - updated 1/18/13
- WiFi Standards - updated 1/18/13
- Roles and Responsibilities for UCSC Electronic Information Resources (PDF) - ON HOLD: updated 1/31/08

